2023 CVE Vulnerabilities
31,245 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-25600 | HIGH | 7.1 | 0.2% | Aug 3, 2023 | An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, lead... |
| CVE-2023-22277 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP... |
| CVE-2023-22317 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP... |
| CVE-2023-22314 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP... |
| CVE-2023-3663 | HIGH | 8.8 | 1.0% | Aug 3, 2023 | In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unau... |
| CVE-2023-3662 | HIGH | 7.3 | 0.2% | Aug 3, 2023 | In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of bina... |
| CVE-2023-21412 | HIGH | 8.8 | 0.5% | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injection... |
| CVE-2023-21411 | HIGH | 8.8 | 0.7% | Aug 3, 2023 | User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary c... |
| CVE-2023-21410 | HIGH | 8.8 | 0.7% | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code e... |
| CVE-2023-21407 | HIGH | 8.8 | 0.6% | Aug 3, 2023 | A broken access control was found allowing for privileged escalation of the operator account to gain administrator priv... |
| CVE-2023-38748 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a ... |
| CVE-2023-38747 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. ... |
| CVE-2023-38746 | HIGH | 7.8 | 0.2% | Aug 3, 2023 | Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By... |
| CVE-2023-38744 | HIGH | 7.5 | 0.7% | Aug 3, 2023 | Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in... |
| CVE-2023-4126 | HIGH | 8.8 | 0.5% | Aug 3, 2023 | Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0. |
| CVE-2023-4125 | HIGH | 8.8 | 0.7% | Aug 3, 2023 | Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0. |
| CVE-2023-39144 | HIGH | 7.5 | 0.4% | Aug 3, 2023 | Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext. |
| CVE-2023-34196 | HIGH | 8.2 | 0.4% | Aug 3, 2023 | In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of... |
| CVE-2023-38956 | HIGH | 7.5 | 0.6% | Aug 3, 2023 | A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files v... |
| CVE-2023-38955 | HIGH | 7.5 | 0.5% | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, ... |
| CVE-2023-36255 | HIGH | 8.8 | 57.4% | Aug 3, 2023 | An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar... |
| CVE-2023-36212 | HIGH | 8.8 | 23.7% | Aug 3, 2023 | File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file... |
| CVE-2023-4078 | HIGH | 8.8 | 0.9% | Aug 3, 2023 | Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ... |
| CVE-2023-4077 | HIGH | 8.8 | 0.9% | Aug 3, 2023 | Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ... |
| CVE-2023-4076 | HIGH | 8.8 | 0.9% | Aug 3, 2023 | Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap ... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now